使用Graph API获取用户信息时遇AADSTS50013签名验证错误
使用On-Behalf-Of流程调用Graph API时遇到AADSTS50013错误
我的Angular应用采用以下调用流程:
Angular应用 → 传递授权码 → 自定义API(生成access-token) → Graph API(用户接口)
错误信息:
发生一个或多个错误。(OnBehalfOfCredential身份验证失败: AADSTS50013: 断言签名验证失败。[原因 - 已找到密钥,但使用该密钥验证签名失败。客户端使用的密钥指纹: 'F8A23743D9CD47B6D1A1FXXXXXXA17A9B1D919EC', 找到的密钥 'Start=10/02/2022 18:06:49, End=10/02/2027 18:06:49']。跟踪ID: 1d326676-f8a5-4410-b4cf-SSS1a9b64800 关联ID: 79ca8aec-bb73-48f9-b0d2-XXXb4226e625 时间戳: 2023-03-10 10:22:27Z)
Azure中配置的应用权限范围:
"openid", "profile", "User.Read.All"
代码实现:
var tenantId= "tenantid"; var clientId= "clientid"; var clientSecret = "secret"; // using Azure.Identity; var options = new OnBehalfOfCredentialOptions { AuthorityHost = AzureAuthorityHosts.AzurePublicCloud }; // 用于通过On-Behalf-Of流程交换的传入令牌 var oboToken = accessToken; var onBehalfOfCredential = new OnBehalfOfCredential(tenantId, clientId, clientSecret, oboToken, options); GraphServiceClient graphClient = new GraphServiceClient(onBehalfOfCredential, scopes); var result = graphClient.Users.GetAsync((requestConfiguration) => { requestConfiguration.QueryParameters.Count = true; requestConfiguration.QueryParameters.Search = "\"displayName:rock\""; requestConfiguration.QueryParameters.Orderby = new string[] { "displayName" }; requestConfiguration.QueryParameters.Select = new string[] { "id", "displayName", "mail" }; requestConfiguration.Headers.Add("ConsistencyLevel", "eventual"); }).Result;
内容的提问来源于stack exchange,提问作者Mannan Bahelim
相关产品推荐
相关产品推荐

